Show filters
121 Total Results
Displaying 41-50 of 121
Sort by:
Attacker Value
Unknown
CVE-2022-45892
Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, multiple Stored Cross-Site Scripting (XSS) vulnerabilities exist: Disclaimer, Search Function, Comments, Batch editing tool, Content Creation, Related Media, Create new user, and Change Username.
0
Attacker Value
Unknown
CVE-2022-45891
Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows attackers to call restricted functions, and perform unauthenticated uploads (Upload2.ashx) or access content uploaded by other users (View.aspx after Ajax.asmx/SaveGrantAccessList).
0
Attacker Value
Unknown
CVE-2022-45890
Disclosure Date: December 25, 2022 (last updated October 08, 2023)
In Planet eStream before 6.72.10.07, a Reflected Cross-Site Scripting (XSS) vulnerability exists via any metadata filter field (e.g., search within Default.aspx with the r or fo parameter).
0
Attacker Value
Unknown
CVE-2022-45889
Disclosure Date: December 25, 2022 (last updated October 08, 2023)
Planet eStream before 6.72.10.07 allows a remote attacker (who is a publisher or admin) to obtain access to all records stored in the database, and achieve the ability to execute arbitrary SQL commands, via Search (the StatisticsResults.aspx flt parameter).
0
Attacker Value
Unknown
CVE-2022-28452
Disclosure Date: April 29, 2022 (last updated February 23, 2025)
Red Planet Laundry Management System 1.0 is vulnerable to SQL Injection.
0
Attacker Value
Unknown
CVE-2022-27850
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Cross-Site Request Forgery (CSRF) in Simple Ajax Chat (WordPress plugin) <= 20220115 allows an attacker to clear the chat log or delete a chat message.
0
Attacker Value
Unknown
CVE-2022-27849
Disclosure Date: April 15, 2022 (last updated February 23, 2025)
Sensitive Information Disclosure (sac-export.csv) in Simple Ajax Chat (WordPress plugin) <= 20220115
0
Attacker Value
Unknown
CVE-2021-42255
Disclosure Date: April 12, 2022 (last updated February 23, 2025)
AppGuard Enterprise before 6.7.100.1 creates a Temporary File in a Directory with Insecure Permissions. Local users can gain SYSTEM privileges because a repair operation relies on the %TEMP% directory of an unprivileged user.
0
Attacker Value
Unknown
CVE-2022-1165
Disclosure Date: April 04, 2022 (last updated February 23, 2025)
The Blackhole for Bad Bots WordPress plugin before 3.3.2 uses headers such as CF-CONNECTING-IP, CLIENT-IP etc to determine the IP address of requests hitting the blackhole URL, which allows them to be spoofed. This could result in blocking arbitrary IP addresses, such as legitimate/good search engine crawlers / bots. This could also be abused by competitors to cause damage related to visibility in search engines, can be used to bypass arbitrary blocks caused by this plugin, block any visitor or even the administrator and even more.
0
Attacker Value
Unknown
CVE-2022-25601
Disclosure Date: February 25, 2022 (last updated February 23, 2025)
Reflected Cross-Site Scripting (XSS) vulnerability affecting parameter &tab discovered in Contact Form X WordPress plugin (versions <= 2.4).
0